CVE-2007-3635 describes multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin for Squirrelmail, affecting versions prior to 2.1. These flaws could allow local, authenticated users to inject commands through unspecified vectors. With a CVSS score of 4.3, this vulnerability is considered low severity, requiring local access and user authentication for potential impact on confidentiality, integrity, and availability. There is no known exploit code available, no evidence of active exploitation, and minimal community or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:squirrelmail:gpg_plugin:2.0:*:*:*:*:*:*:* | ||
1.4.10aCPE matchmatch criteria | cpe:2.3:a:squirrelmail:squirrelmail:1.4.10a:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.